US11520939B2

Protecting computer systems from malicious USB devices via a USB firewall

Summary by NHIP

USB Traffic Policy Firewall

The system intercepts USB traffic to determine if a device has a stored policy for blocking, allowing, or sanitizing data. If no policy exists, it prompts a user to select an action, then either enforces the choice or routes untrusted packets to a network sandbox for translation before returning sanitized data.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

USB traffic is intercepted between a USB device and a computer system. It is determined whether the USB device has previously had a policy associated with it as to whether USB traffic from the device should be blocked, allowed, or sanitized. In response to not having a previous policy for the USB device, a request is made for a user to be prompted to provide a policy of one of block, allow, or sanitize for the USB device. In response to a user-provided-policy, one of the following are performed: blocking the traffic, allowing the traffic, or sanitizing the traffic between the USB device and the computer system. Apparatus, methods, and computer program products are disclosed.

US11520939B2, drawing sheet 1
Sheet 1 of 8

Term

12.2 yearsleft in the term

Expires 10 December 2038, including 633 days of term adjustment.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

20 claims: 4 independent, 16 dependent

  1. 1
    Broadest claimClaim Score 55, average(NHIP)A method, comprising:intercepting universal serial bus (USB) traffic between a USB device and a computer system;determining whether the USB device has previously had a policy associated with it as to whether USB traffic from the device should be blocked, allowed, or sanitized, wherein any one of blocked, allowed, or sanitized can be indicated by the policy;in response to not having a previous policy for the USB device, requesting that a user be prompted to provide a policy of one of block, allow, or sanitize for the USB device to provide a user-provided policy, wherein any one of block, allow, or sanitize can be selected and indicated by the user in the user-provided policy;and in response to and based on the user-provided policy, performing the selected one of blocking the traffic, allowing the traffic, or sanitizing the traffic from the USB device toward the computer system, wherein sanitizing the traffic comprises changing or translating certain commands or requests that are known to be problematic into other commands or requests that are known to be good, wherein sanitizing the traffic between the USB device and the computer system further comprises sending untrusted packets from the USB device through the computer system and toward a sandbox on a network, and receiving sanitized packets through the computer system and from the sandbox.
  2. 8
    An apparatus, comprising:one or more memories comprising computer readable code stored thereon;one or more processors, the one or more processors configured, in response to retrieval and execution of at least a portion of the computer readable code, to cause the apparatus to perform operations comprising: intercepting universal serial bus (USB) traffic between a USB device and a computer system;determining whether the USB device has previously had a policy associated with it as to whether USB traffic from the device should be blocked, allowed, or sanitized, wherein any one of blocked, allowed, or sanitized can be indicated by the policy;in response to not having a previous policy for the USB device, requesting that a user be prompted to provide a policy of one of block, allow, or sanitize for the USB device to provide a user-provided policy, wherein any one of block, allow, or sanitize can be selected and indicated by the user in the user-provided policy;and in response to and based on the user-provided policy, performing the selected one of blocking the traffic, allowing the traffic, or sanitizing the traffic from the USB device toward the computer system, wherein sanitizing the traffic comprises changing or translating certain commands or requests that are known to be problematic into other commands or requests that are known to be good, wherein sanitizing the traffic between the USB device and the computer system further comprises sending untrusted packets from the USB device through the computer system and toward a sandbox on a network, and receiving sanitized packets through the computer system and from the sandbox.
  3. 19
    An apparatus, comprising:one or more memories comprising computer readable code stored thereon;one or more processors, the one or more processors configured, in response to retrieval and execution of at least a portion of the computer readable code, to cause the apparatus to perform operations comprising: intercepting universal serial bus (USB) traffic between a USB device and a computer system;determining whether the USB device has previously had a policy associated with it as to whether USB traffic from the device should be blocked, allowed, or sanitized, wherein any one of blocked, allowed, or sanitized can be indicated by the policy;in response to not having a previous policy for the USB device, requesting that a user be prompted to provide a policy of one of block, allow, or sanitize for the USB device to provide a user-provided policy, wherein any one of block, allow, or sanitize can be selected and indicated by the user in the user-provided policy;and in response to and based on the user-provided policy, performing the selected one of blocking the traffic, allowing the traffic, or sanitizing the traffic from the USB device toward the computer system, wherein sanitizing the traffic comprises changing or translating certain commands or requests that are known to be problematic into other commands or requests that are known to be good, wherein sanitizing the traffic between the USE device and the computer system further comprises sending one or more untrusted packets from the USB device through the computer system and toward a sandbox on a network, receiving an abstract representation of the USB device through the computer system and from the sandbox, the abstract representation providing at least a device class and generic commands for the USB device, and implementing the abstract representation of the USB device to sanitize the one or more entrusted packets that were sent and to sanitize any additional packets from the USB device toward the computer system, the sanitizing comprising translating commands into a sanitized version of commands with a same semantic meaning for the device class.
  4. 20
    A computer program product comprising a non-transitory computer readable storage medium having program instructions embodied therewith, the program instructions executable by a device to cause the device to perform operations comprising:intercepting universal serial bus (USB) traffic between a USB device and a computer system;determining whether the USB device has previously had a policy associated with it as to whether USB traffic from the device should be blocked, allowed, or sanitized, wherein any one of blocked, allowed, or sanitized can be indicated by the policy;in response to not having a previous policy for the USB device, requesting that a user be prompted to provide a policy of one of block, allow, or sanitize for the USB device to provide a user-provided policy, wherein any one of block, allow, or sanitize can be selected and indicated by the user in the user-provided policy;and in response to and based on the user-provided policy, performing the selected one of blocking the traffic, allowing the traffic, or sanitizing the traffic from the USB device toward the computer system, wherein sanitizing the traffic comprises changing or translating certain commands or requests that are known to be problematic into other commands or requests that are known to be good, wherein sanitizing the traffic between the USB device and the computer system further comprises sending untrusted packets from the USB device through the computer system and toward a sandbox on a network, and receiving sanitized packets through the computer system and from the sandbox.